Schneider Electric IGSS Mobile local information leakage (CVE-2017-9969)
Schneider Electric IGSS Mobile local information leakage (CVE-2017-9969)
Release date:
Updated on:
Affected Systems:
Schneider Electric IGSS Mobile <= 3.01
Description:
Bugtraq id: 103046
CVE (CAN) ID: CVE-2017-9969
Schneider Electric IGSS is a SCADA System for process control and monitoring.
Schneider Electric IGSS Mobile 3.01 and earlier versions have the information leakage vulnerability, which allows attackers to obtain sensitive information through plain text in the configuration.
<* Source: Alexander Bolshev (IOActive)
*>
Suggestion:
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151152.htm